Calisto
Techniques Used |
||||
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1560 | .001 | Archive Collected Data: Archive via Utility |
Calisto uses the |
Enterprise | T1136 | .001 | Create Account: Local Account |
Calisto has the capability to add its own account to the victim's machine.(Citation: Symantec Calisto July 2018) |
Enterprise | T1543 | .001 | Create or Modify System Process: Launch Agent |
Calisto adds a .plist file to the /Library/LaunchAgents folder to maintain persistence.(Citation: Securelist Calisto July 2018) |
Enterprise | T1555 | .001 | Credentials from Password Stores: Keychain |
Calisto collects Keychain storage data and copies those passwords/tokens to a file.(Citation: Securelist Calisto July 2018)(Citation: Symantec Calisto July 2018) |
Enterprise | T1074 | .001 | Data Staged: Local Data Staging |
Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration.(Citation: Securelist Calisto July 2018)(Citation: Symantec Calisto July 2018) |
Enterprise | T1564 | .001 | Hide Artifacts: Hidden Files and Directories |
Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration.(Citation: Securelist Calisto July 2018)(Citation: Symantec Calisto July 2018) |
Enterprise | T1070 | .004 | Indicator Removal: File Deletion |
Calisto has the capability to use |
Enterprise | T1056 | .002 | Input Capture: GUI Input Capture |
Calisto presents an input prompt asking for the user's login and password.(Citation: Symantec Calisto July 2018) |
Enterprise | T1036 | .005 | Masquerading: Match Legitimate Name or Location |
Calisto's installation file is an unsigned DMG image under the guise of Intego’s security solution for mac.(Citation: Securelist Calisto July 2018) |
Enterprise | T1569 | .001 | System Services: Launchctl |
Calisto uses launchctl to enable screen sharing on the victim’s machine.(Citation: Securelist Calisto July 2018) |
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.